External API Vulnerability Assessment via SBOM Querying
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud Native architectures increase the attack surface for microservice-based applications, with organizations lacking visibility into external API endpoints' software bill of materials (SBOMs), leading to inadequate vulnerability assessments and mitigation strategies.
Innovation Solution
An observability intelligence platform and application security manager facilitate SBOM visibility and risk assessment for external API endpoints by querying and analyzing SBOMs, generating vulnerability assessments, and triggering mitigation actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If organizations adopt Cloud Native architectures with microservice-based systems, then application development flexibility and scalability are improved, but the attack surface increases and vulnerability exposure worsens
Solution Approach 1:
The patent introduces an intermediary security assessment system that acts as a mediator between internal applications and external API endpoints. This system queries SBOMs from external APIs, assesses vulnerabilities, and provides visibility without requiring direct exposure of internal systems to external threats, thus maintaining flexibility while reducing attack surface impact
Solution Approach 2:
The system performs preliminary vulnerability assessments by querying SBOMs and identifying security risks before they can be exploited. By conducting security assessments in advance and integrating them into the development lifecycle, the system enables organizations to address vulnerabilities proactively rather than reactively to attacks
2Productivity
If developers produce APIs quickly without regard to best practices, then development productivity is improved, but API vulnerability identification capability worsens
Solution Approach 1:
The patent implements a feedback mechanism where vulnerability assessment results from SBOM analysis are fed back to developers and security teams. This continuous feedback loop enables quick identification of issues in rapidly developed APIs, allowing for immediate remediation while maintaining high development velocity
Solution Approach 2:
The system replaces manual vulnerability identification processes with automated SBOM querying and analysis mechanisms. This substitution enables precise vulnerability detection across quickly produced APIs without requiring manual security review of each API, thus maintaining both speed and accuracy
3Reliability
If organizations rely on internal API analysis tools, then internal security assessment capability is improved, but visibility into external API endpoint vulnerabilities worsens
Solution Approach 1:
The patent creates a universal security assessment capability that can evaluate both internal applications and external API endpoints through a single system. By querying SBOMs from external APIs and assessing their vulnerabilities alongside internal systems, the system provides comprehensive visibility without requiring separate tools, thus maintaining internal assessment reliability while gaining external visibility
Data Source
AI summary
In one embodiment, external API vulnerability assessments may include detecting, by a process, usage of an external application programming interface in execution of an application; transmitting, by the process, a query to the external application programming interface for a list of one or more components of the external application programming interface; generating, by the process, a vulnerability assessment for the application based on a response to the query; and performing, by the process, one or more mitigation actions based on the vulnerability assessment.


